A strong password is no longer enough. Passwords get leaked in data breaches, guessed, or stolen through fake login pages. Two-factor authentication (2FA) adds a second lock: even if someone has your password, they can't get in without a code or approval from your phone. This step-by-step guide shows you how to set it up on the accounts that matter most.

What Is Two-Factor Authentication?

Two-factor authentication means proving who you are with two different kinds of evidence:

  1. Something you know — your password or PIN.
  2. Something you have — your phone, a security key or an authenticator app.

Some services also use something you are, such as your fingerprint or face.

When 2FA is on, logging in from a new device requires both your password and the second factor. This blocks the overwhelming majority of automated account-takeover attempts.

Types of Two-Factor Authentication, From Weakest to Strongest

  • SMS codes: A code is texted to your phone. Much better than nothing, but vulnerable to SIM-swap fraud and phishing.
  • Email codes: Only as secure as your email account.
  • Authenticator apps: Apps like Google Authenticator, Microsoft Authenticator or Authy generate a new six-digit code every 30 seconds on your phone, even offline. Recommended for most people.
  • Push approvals: You tap "Yes, it's me" on a prompt. Convenient, but never approve a prompt you didn't trigger.
  • Passkeys and security keys: Passkeys use your phone's or computer's fingerprint/face unlock; physical keys (like YubiKey) plug in or tap. These resist phishing and are the strongest option.

Before You Start

  1. Install an authenticator app on your phone.
  2. Make sure your phone has a screen lock.
  3. Have a safe place (a password manager or a written note stored securely) for backup codes.

Google / Gmail

  1. Go to myaccount.google.com → Security.
  2. Under How you sign in to Google, select 2-Step Verification and follow the prompts.
  3. Add an Authenticator app and consider adding a passkey.
  4. Download and save your backup codes.

Your Google account protects Gmail, Google Drive, YouTube and often your Android phone, so secure it first.

Microsoft / Outlook

  1. Sign in at account.microsoft.com → Security → Advanced security options.
  2. Turn on Two-step verification.
  3. Add the Microsoft Authenticator app.

WhatsApp

  1. Open Settings → Account → Two-step verification → Turn on.
  2. Create a six-digit PIN and add an email address for recovery.

This stops someone registering your WhatsApp number on their phone, a common scam.

Facebook and Instagram

  1. Open Accounts Centre → Password and security → Two-factor authentication.
  2. Choose your account and select Authentication app (recommended).
  3. Save the recovery codes.

X (Twitter), TikTok and others

Look under Settings → Security for "Two-factor authentication" or "2-step verification". The process is similar on almost every platform.

Banking apps

Most banks already use one-time codes, hardware tokens or app approvals. Make sure notifications are on, set a strong app PIN, and never share codes with anyone — see our guide on phishing scams.

Two-Factor Authentication for Small Businesses

If you run a business, two-factor authentication is just as important for your company accounts as for your personal ones. Start with:

  • Business email and domain accounts — whoever controls these can reset every other login.
  • Banking and payment platforms such as your bank's business app, Paystack, Flutterwave, Stripe or PayPal.
  • Website and hosting dashboards, including your domain registrar.
  • Social media pages that customers rely on to contact you.
  • Accounting and cloud storage tools that hold invoices and customer data.

Ask every staff member to turn on 2FA for work accounts, and remove access promptly when someone leaves. Where possible, give each person their own login instead of sharing one password — shared accounts make 2FA awkward and leave no record of who did what. Our business guides cover more ways to protect a small company.

Protect Your Email First

Your email account can reset the passwords of almost everything else. If you only set up two-factor authentication on one account today, make it your main email.

How to Avoid Getting Locked Out

  • Save backup codes somewhere safe, not only on your phone.
  • Add a second method, such as a backup phone number or a second security key.
  • Transfer your authenticator before changing phones — Google Authenticator and Microsoft Authenticator both offer account transfer or cloud backup.
  • Keep your recovery email and phone number up to date.

Common Myths About 2FA

  • "It's too complicated." After setup, you'll usually only see a code prompt when logging in on a new device.
  • "Hackers can bypass it anyway." Advanced attacks exist, but 2FA stops the vast majority of everyday attacks. Phishing-resistant passkeys close most of the remaining gaps.
  • "I have nothing worth stealing." Criminals use hijacked accounts to scam your contacts, send spam or steal money.

Frequently Asked Questions

What happens if I lose my phone?

Use your backup codes or backup method to sign in, then remove the lost phone from your account and set up 2FA on your new device. This is why saving backup codes is essential.

Is SMS two-factor authentication safe?

It's much safer than a password alone, but an authenticator app or passkey is better because SMS can be intercepted through SIM-swap fraud.

Do I need a different authenticator app for each account?

No. One authenticator app can hold codes for all your accounts.

What is a passkey?

A passkey replaces passwords with your device's fingerprint, face or PIN. It can't be phished because it only works on the genuine website.

Final Thoughts

Setting up two-factor authentication takes a few minutes per account and dramatically reduces your risk of being hacked. Start with your email, then your banking, social media and cloud storage. For more practical security tips, read how to protect your phone from hackers and explore our Tech section.